That sounds like a mod, or someone trying an pseudo security trick. I.e. they place it there to see if it prevents hackers. In my mind, it would push them further to try and hack my board, I woudln't want that.
But as far as the end-user goes, the only more-secure thing you can do is put phpBB on an httpS connection. That's about it. If you apply mods, see what they modify, and make sure it's still secure. The most problems come from people applying mods and then leaving their board open, and of course hackers being @ssh0l3s and trying to hack boards....